RLSA-2026:65162

    Dashboard / Vulnerabilities / RLSA-2026:65162

    RLSA-2026:65162

    Published: 9 Sept 2026Last Modified: 9 Sept 2026
    Upstream:

    Summary: Important: gpsd security update

    Details: gpsd is a service daemon that mediates access to a GPS sensor connected to the host computer by serial or USB interface, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer. With gpsd, multiple GPS client applications (such as navigational and war-driving software) can share access to a GPS without contention or loss of data. Also, gpsd responds to queries with a format that is substantially easier to parse than NMEA 0183. The Rocky Enterprise Software Foundation support for this package is limited. See https://access.redhat.com/support/policy/gpsd-support for more details. Security Fix(es): * gpsd: gpsd: Arbitrary OS command execution via code injection in gpsprof utility (CVE-2026-60122) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Affected packages

    Package

    Name: gpsd

    Purl: pkg:rpm/rocky-linux/gpsd?distro=rocky-linux-10&epoch=1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1:3.26.1-3.el10_2.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RLSA-2026:65162 | CVE-DB